Privacy Policy
Last updated 3 September 2026
This Privacy Policy explains how Salveva (“we”, “us”, “our”) collects, uses, shares and protects your personal data when you use our Service. We handle your data in line with the EU General Data Protection Regulation (Regulation 2016/679) and Italian data-protection law.
1. Who is responsible for your data
Agus Friastana, of [TO CONFIRM: mail-forwarding or registered-office address], is the controller of the personal data you provide through the Service. For anything in this policy, or to exercise the rights in section 10, email us at hello@salveva.com.
2. Data we collect
Data you give us
- Account details — your name, email address, phone number and password (stored only in hashed form).
- Booking details — guest names, dates, and the information an accommodation provider needs to hold a room.
- Trip descriptions you type into the planner, and any messages you send us.
Data we collect automatically
- Usage and device data — pages viewed, approximate location, IP address, browser and device type.
- Cookies and similar technologies (see section 6).
Payment data
We do not collect it. You pay the accommodation supplier on the supplier’s own secure checkout page, and your card details are entered there. They never reach our systems, and we are not the controller of them — the supplier and their payment processor are, under their own privacy policies.
3. How we use your data, and on what basis
Each purpose below has a legal basis under Article 6 of the GDPR:
- Running your account and passing your booking to a provider — performance of a contract with you (Art. 6(1)(b)).
- Generating and saving itineraries — performance of a contract, or our legitimate interest in providing the planner to visitors without an account (Art. 6(1)(b), 6(1)(f)).
- Service emails — confirmations and anything else you need in order to travel: performance of a contract (Art. 6(1)(b)).
- Newsletters — your consent, withdrawable in one tap from any email (Art. 6(1)(a)).
- Analytics — your consent, given on the banner and withdrawable at any time (Art. 6(1)(a)).
- Security, fraud prevention and keeping the Service working — our legitimate interests (Art. 6(1)(f)).
- Meeting accounting and legal obligations — legal obligation (Art. 6(1)(c)).
4. The AI planner
The trip description you type is sent to our model provider to generate an itinerary. Don’t include anything sensitive in it — it is a description of a holiday, and it does not need your health, beliefs or finances. The provider processes it on our instructions as a processor and does not use it to train models.
The planner does not make decisions producing legal or similarly significant effects about you, so Article 22 of the GDPR does not apply to it. It suggests an itinerary; every booking is a choice you make.
5. When we share your data
- Accommodation providers and the supplier platform that connects us to them — the guest names and dates needed to hold your booking.
- Processors acting on our instructions — hosting, email delivery, error monitoring, and the model provider behind the planner.
- Authorities — where we are legally required to, or to establish or defend legal claims.
We do not sell your personal data, and we do not share it for advertising.
6. Cookies
We use cookies that are essential for the Service to work — keeping you signed in, and remembering your currency and language. The currency cookie is set on your first visit, before you have chosen anything, because prices are calculated on our servers and they need to know which currency to quote in; it holds nothing but a three-letter currency code. Essential cookies cannot be switched off without affecting how the Service works.
For analytics we use Google Analytics 4, and it measures nothing until you agree to it. The Google tag is present on every page, but it loads under Google’s Consent Mode with every storage permission set to “denied”: until you choose “Allow analytics” on the banner we show on your first visit, it writes no cookie and stores no identifier, so nothing it sends can be tied to you or to your next visit. Google does still receive a basic, cookieless signal that a page was viewed. We never grant the advertising permissions at all — this is analytics, not advertising. If you decline, we do not ask again and nothing about the Service changes.
If you allow it, Google Analytics sets cookies and receives your IP address (truncated), the pages you view and basic device information, as our processor. You can change your mind at any time using the Analytics link in the footer of any page: switching it off returns the tag to its denied state and deletes the analytics cookies it had set. Clearing your browser cookies also resets the choice, and we will ask again.
7. International transfers
Some of our processors are established outside the European Economic Area. Where personal data is transferred there, we rely on an adequacy decision where one covers the country, and otherwise on the European Commission’s Standard Contractual Clauses together with any additional measures the transfer requires. You can ask us which safeguard applies to a particular transfer.
8. How long we keep it
- Account data — while your account is open, and up to 12 months after you close it.
- Booking records — for as long as accounting and tax law requires, which in Italy is ten years.
- Itineraries you have not saved to an account — 90 days.
- Newsletter subscriptions — until you unsubscribe.
- Analytics data — for the retention period set in Google Analytics, currently 14 months.
9. How we protect it
Traffic is encrypted in transit, passwords are stored only as salted hashes, and access to production data is restricted to those who need it. No system is perfectly secure, but we take these obligations seriously and will tell you and the supervisory authority about a breach where the law requires it.
10. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- have inaccurate data corrected, and incomplete data completed;
- have data erased where the grounds in Article 17 apply;
- restrict or object to processing based on our legitimate interests;
- receive data you gave us in a portable format, and have it sent to another controller;
- withdraw consent at any time, without affecting processing already carried out under it.
Email hello@salveva.com and we will respond within one month. If you are not satisfied you can complain to the Garante per la protezione dei dati personali, or to the supervisory authority where you live or work.
11. Children
The Service is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy. The date at the top of the page shows when it last changed, and where a change materially affects your rights we will tell you.
13. Contact
Questions about this policy? Email hello@salveva.com or use our contact page. See also our Terms of Service.